Last updated October 2026.
How Nettle is deployed and isolated, how customer data is handled and audited, and where we are on security certifications.
For live service health, see our status page at status.nettle.llc.
System status
Live service health is published at status.nettle.llc, hosted independently by Better Stack. It monitors:
nettle.llc: this website
app.nettle.llc: the Nettle community edition, a public instance that works on public data only. Customer deployments are separate: they run in the customer’s own environment, behind authentication
app.nettle.llc/mcp: the community edition’s MCP server that AI agents connect to
Kubernetes cluster services: the infrastructure that runs the application
For each service it shows current status and 90-day uptime, along with scheduled maintenance and previous incidents. Our availability target for cluster services is 99.9%.
Deployment and isolation
Customer deployments of Nettle run inside your own cloud VPC or on-premises. Each deployment sits behind OIDC authentication, and external connections stay disabled unless you ask for them.
Our public community edition runs only on public datasets and is kept separate from customer deployments.
Nettle has no external dependencies other than calls to the LLM models you choose. Telemetry is used only for monitoring and can be switched off for high-security environments. Air-gapped deployment is possible with suitable model choices, but it is not offered today.
Data handling and deletion
When a user deletes a dataset, it first moves to a 72-hour quarantine so it can be recovered if needed. After that it is purged, leaving only a minimal tombstone recording that the dataset once existed. Permanent hard deletes are also available through the MCP server and the API.
Datasets and results export in open formats (DuckDB, Parquet, Iceberg and SQLite), so your data is never locked in.
Nettle detects columns that contain personal data and flags them for review.
Audit trail and oversight
Every ingest records who triggered it (through the UI, the API or an AI agent), along with IP address, location and timestamp. Every job keeps a full log stream, including the cost of each LLM call.
Column classifications can be reviewed and overridden inline, with filters that surface low-confidence and personal-data columns first. Datasets are soft-deleted with a restore path rather than destroyed.
Nettle works with both frontier and open-weight models, so you can choose providers that fit your security posture and existing provider agreements. Our governance tooling gives visibility into AI costs, token use and compute.
Certifications and testing
Our roadmap targets SOC 2 Type II, ISO 27001, ISO 42001, HIPAA and PCI DSS by Q2 2027, with FedRAMP, StateRAMP and TX-RAMP to follow as customers need them.
Independent penetration testing is scheduled for Q1 2027.
Security questions
For security reviews, questionnaires or due diligence, or to report a security concern:
Email us at info@nettle.llc